Secrets openly shown in metric name #2163
Unanswered
TimShilov
asked this question in
Q&A / Need Help
Replies: 1 comment
-
This should not happen, created #2165 for this as a bug. Sorry about that! |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I just noticed that the metric name is created based on the MySQL scaler connection string (which is a secret and is stored in a Secret) which I think is not great. Is there any reason why it's not hashed?
Secrets are secrets and they should not be lying around. And Keda should not take something that is Secret and turn it into a plain text.
Basically, anyone with access to HPA can see the secret which is unexpected to me.
The screenshot is taken from GKE UI. "Deployment" -> "Details".
Beta Was this translation helpful? Give feedback.
All reactions